DocumentCode :
3100759
Title :
MAVMM: Lightweight and Purpose Built VMM for Malware Analysis
Author :
Nguyen, Anh M. ; Schear, Nabil ; Jung, HeeDong ; Godiyal, Apeksha ; King, Samuel T. ; Nguyen, Hai D.
Author_Institution :
Dept. of Comput. Sci., Univ. of Illinois at Urbana-Champaign, Urbana, IL, USA
fYear :
2009
fDate :
7-11 Dec. 2009
Firstpage :
441
Lastpage :
450
Abstract :
Malicious software is rampant on the Internet and costs billions of dollars each year. Safe and thorough analysis of malware is key to protecting vulnerable systems and cleaning those that have already been infected. Most current state-of-the-art analysis platforms run alongside the malware, increasing their detectability. This reduces the value of analysis because some malware is known to behave differently when being analyzed. Virtualization offers a compelling platform for malware analysis, with strong isolation and the ability to save and restore guest state. Current virtual machine monitors (VMMs), however, are not designed for malware analysis. Due to their complexity, they often fail to provide transparency and even expose vulnerabilities which could be exploited by the malware running inside guest system. We propose a lightweight VMM (namely MAVMM) that is designed specially for a single job: malware analysis. MAVMM does not implement unnecessary virtualization features commonly found in general purpose hypervisors, including virtual device emulation. We take advantage of hardware virtualization support to make MAVMM more simple, secure and transparent. In this paper, we describe the design and implementation of MAVMM, and the features that we can extract from programs running inside the guest OS. We evaluate our platform in three aspects: functionality, detectability and performance. We show that our system can extract useful information from malicious software, and that it is not susceptible to known virtualization detection techniques.
Keywords :
invasive software; Internet; detectability; general purpose hypervisors; hardware virtualization support; malicious software; malware analysis; virtual device emulation; virtual machine monitors; virtualization detection; vulnerable systems; Application software; Computer science; Computer security; Costs; Data mining; Emulation; Internet; Platform virtualization; Virtual machine monitors; Virtual machining; Malware analysis; security; virtual machine monitor;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 2009. ACSAC '09. Annual
Conference_Location :
Honolulu, HI
ISSN :
1063-9527
Print_ISBN :
978-0-7695-3919-5
Type :
conf
DOI :
10.1109/ACSAC.2009.48
Filename :
5380697
Link To Document :
بازگشت